RSOX is a Rust-based SOCKS proxy relay used as a post-compromise tunneling utility in intrusion campaigns attributed to a likely initial access broker associated with ransomware follow-on activity. It has been observed in operations that begin with social engineering through Microsoft Teams vishing and Quick Assist remote-access sessions, after which attackers deploy additional tooling to maintain access, conduct reconnaissance, exfiltrate data, and enable operator-controlled network pivoting.
RSOX is delivered as a Microsoft Installer package and functions as a reverse proxy component that relays SOCKS traffic over WebSocket connections protected with TLS. Its protocol uses token-based authentication and JSON-formatted command messages, with observed command handling for session setup, SOCKS enablement, connection management, data relay, teardown, keepalive-style interaction, and process termination. This design allows operators to establish tunneled access through compromised Windows hosts and support further post-exploitation activity inside victim environments.
RSOX has been deployed alongside other tooling including GoGRPC, BlindDoor, RevSocket, PyGRPC, and S3Siphon. Within that toolset, RSOX appears to serve the network tunneling and proxying role rather than primary initial access or standalone persistence. Observed targeting is consistent with corporate environments selected after attacker-led valuation and reconnaissance, particularly in campaigns assessed as preparatory access operations for later extortion or ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
ThreatLabz analyzed the functionality of these tools along with the command-and-control (C2) communication methods used by the attackers.
The threat actor also deploys SOCKS proxy tools that also use gRPC or WebSockets to communicate with the C2 server.
RevSocket : proxy SOCKS inverse en Go ... PyGRPC : proxy SOCKS inverse en Python ... RSOX : ... proxy SOCKS relay
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based SOCKS relay/proxy delivered via MSI, using WebSocket over TLS, token authentication, and JSON-based command messaging for remote connectivity and control.
A tool used in the same campaign, likely supporting remote access or tunneling within the intrusion chain.
Additional malware used in the same campaigns alongside GoGRPC.
A Rust-based SOCKS proxy relay delivered via MSI that uses WebSockets over TLS for C2, authenticates with a token, supports opening and relaying TCP streams, heartbeats, disabling SOCKS, and kill commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.